Menu

Shared Android device quickstart

Normally, Android devices only support one user account, and don't provide a sign-in system. However, there are many cases in an enterprise's activities where a device would be more fit for purpose if it could support multiple identities, such as an on-premises device that's transferred to a different employee during each work shift, a freely-accessible device in a common room, or a shared device for visitors and guests.

Knox Manage allows you to enroll Android devices in a special shared mode, which supports the authentication of multiple assigned users through the sign-in screen on the Knox Manage agent. You can configure a shared device so that when a user signs in, it applies settings and a profile that is either generic or unique to that user, allowing varying levels of user access and permissions depending on the user's role and needs.

To better isolate data between user accounts on the device, there are two types of shared device:

Shared device type Purpose
Temporary For guests and visitors. Data and installed apps on the device are deleted when the device user signs out, meaning no locally stored information is shared between users or between sessions.
Persistent For shift workers. Data and installed apps on the device are retained when the device user signs out, meaning locally stored information is shared between users and between sessions.

Supported devices

The following devices can be enrolled in shared mode:

  • Samsung Galaxy Tab devices running Android 9 or higher
  • Non-Samsung devices running Android 9 or higher

Set up a shared Android device

The process to set up a shared device has the following stages:

  1. Create a staging user
  2. Configure the staging user settings
  3. Enroll the device

Register a staging user

Since Android can't operate without at least one active user, shared devices require a staging user between regular user sessions. The staging user is an account with a supervisory scope that carries the basic device configuration and settings, and hosts a base session in the operating system that provides the sign-in screen to device users.

When a device is being prepared to enter shared mode, it must be provisioned with the staging user.

To create a staging user:

  1. Go to User, then click Add.
  2. Fill in the basic and required user account information. For more detailed instructions, see Register a single user.
  3. Set Staging user to Yes.
  4. Make sure Using Type is set to Shared Device.
  5. Set Shared device type to Temporary or Persistent according to your deployment needs.
  6. Click Save and confirm.

Configure the staging user settings

Next, configure the device settings for the staging user that apply between regular user sessions. You can configure generic settings that apply to all staging users in your tenant, or create more specific configurations that only apply to select staging users. If you configure both, a specific configuration overrides the generic settings.

To configure the staging user settings:

  1. Go to Setting > Configuration > Staging Device
  2. Next, choose whether you want the configuration to be generic to all staging users on the Default tab, or click add to add a unique configuration for your shared device.
  3. As needed, set Utilities Setting to Allow and select which Android features to enable for the staging user:

    • Power
    • System Status Bar
    • Notification Bar
    • Key Guard
  4. As needed, under Device Setting, select the items that the staging user can access in the Settings app on the device:

    • Wi-Fi
    • Bluetooth
    • NFC
    • Mobile Data
    • Mobile Networks
    • Hotspot
    • Location
  5. As needed, turn on Wi-Fi and preconfigure an access point that the device can connect to during staging user sessions.
  6. If you're creating a configuration that's specific to the staging user, click Select Staging User and select the staging user from the list.
  7. Click Save & Apply to finish configuring the staging user settings.

Enroll the device

Lastly, after configuring the staging user and its settings, you must enroll the device and activate shared mode:

  1. Go to User, then take note of the staging user's ID.
  2. Then, enroll the device with the staging user through one of these methods:

    Regardless of the method you choose, make sure you enter the staging user ID, or the device won't enroll in shared mode.

  3. After enrollment, go to Device, then search for and find the device. If it successfully enrolled as a shared device, its value in the Platform & Management Type column is Shared followed by the type (Temporary or Persistent).

    A device on the Device page with the Android Shared (Persistent) label.

Device user sign-in

When the shared device is enrolled and deployed to the field, it displays the sign-in screen when no user session is active. A user starts a session by signing in with their Knox Manage account credentials.

The sign-in screen in the Knox Manage agent.

When the device user has finished their activities, they can end their session by tapping Check Out in the persistent Knox Knox notification.

The sign-out notification on the device.

If it's a temporary shared device, the app and user data on the device is erased.

Policies and device commands for shared devices

Shared devices can receive device commands and policies that are compatible with work profiles. Policies designed for fully managed mode won't take effect.

Exit shared mode

In case of emergencies or issues with the shared device mode, the device user can run the Exit Shared Device Mode action on the device to exit shared mode. Once they submit the action, the device user enters a passcode issued to them by an admin.

Use Knox Remote Support

You can perform a remote support session on a shared device with Knox Remote Support, provided the Knox Remote Support agent is first installed on the device.

In order for the agent to be functional and accessible, it must be:

  1. Installed to the personal or primary profile of the device.
  2. Accessed during a staging user session, not a temporary or persistent user session.

To install the Knox Remote Support agent on a shared device, the staging user must:

  1. Open the Knox Manage agent, then select Service Desk on the sign-in screen or in the navigation bar.
  2. Select Download Remote Support app. The Knox Remote Support agent downloads and installs.

Once installed, the agent launches and shows a remote support access code, indicating that it's ready for a remote session.

See also